PT-2025-13599 · Unknown · Netty Quic Codec
Published
2025-03-28
·
Updated
2025-03-31
·
CVE-2025-29908
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Netty QUIC codec versions prior to 0.0.71.Final
Description
A hash collision vulnerability in the Netty QUIC codec allows remote attackers to cause a considerable CPU load on the server by initiating connections with colliding Source Connection IDs (SCIDs), resulting in a Hash DoS attack.
Recommendations
For versions prior to 0.0.71.Final, update to version 0.0.71.Final to resolve the issue. As a temporary workaround, consider restricting access to the
quiche module or limiting the number of connections to minimize the risk of exploitation.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty Quic Codec